AkamaiGHost
tcp/443
nginx 1.25.5
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490dbaf340e11d5499ec0c183c904cf51702ce80e41c7bae1e177
GraphQL introspection enabled at /api/gql Types: 222 (by kind: ENUM: 10, INPUT_OBJECT: 39, INTERFACE: 4, OBJECT: 156, SCALAR: 8, UNION: 5) Operations: - Query: Query | fields: search, searchAutoComplete, startPage, store, stores - Mutation: Mutation | fields: addToCustomerProductList, createCustomerProductList, deleteCustomerProductList, subscribeToNewsletter, subscribeToStockNotifications Directives: deprecated, include, skip (total: 3)
Severity: medium
Fingerprint: c2db3a1c40d490dbaf340e11d5499ec0c183c904cf51702ce80e41c7ec9d0de2
GraphQL introspection enabled at /api/gql Types: 222 (by kind: ENUM: 10, INPUT_OBJECT: 39, INTERFACE: 4, OBJECT: 156, SCALAR: 8, UNION: 5) Operations: - Query: Query | fields: search, searchAutoComplete, startPage, store, stores - Mutation: Mutation | fields: addToCustomerProductList, createCustomerProductList, deleteCustomerProductList, subscribeToNewsletter, subscribeToStockNotifications Directives: deprecated, include, skip (total: 3) Detected: Magento
Open service 95.101.54.216:443 · app-staging.cgnportal.de
2026-01-23 00:34
HTTP/1.1 200 OK
Content-Type: text/html
x-envoy-upstream-service-time: 4
Content-Length: 533
Expires: Fri, 23 Jan 2026 00:34:29 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Fri, 23 Jan 2026 00:34:29 GMT
Connection: close
Alt-Svc: h3=":443"; ma=93600
Strict-Transport-Security: max-age=600 ; includeSubDomains
Akamai-GRN: 0.d436655f.1769128469.6da8e4d
Page title: AppPortal | CGN Portal
<!doctype html>
<html lang="en">
<head>
<meta charset="utf-8" />
<title>AppPortal | CGN Portal</title>
<base href="/" />
<meta name="viewport" content="width=device-width, initial-scale=1" />
<link rel="icon" type="image/x-icon" href="/favicon.ico" />
<script nonce="9cede892ba77984420759c883b13fc0c" type="module" crossorigin src="/assets/index-DfZo5efr.js"></script>
<link rel="stylesheet" crossorigin href="/assets/index-q5zoz64v.css">
</head>
<body>
<div id="root"></div>
</body>
</html>
Open service 95.101.54.216:443 · www.chevalier.fi
2026-01-22 20:51
HTTP/1.1 200 OK Server: nginx/1.25.5 Content-Type: text/html Link: </static/css/style-StartPage-StartPage-272f8fcf.chunk.css>; as=style; rel=preload, </static/css/style-726-eb77abed.chunk.css>; as=style; rel=preload, </static/css/style-cdee2ed2.css>; as=style; rel=preload, </static/js/react.6.2.9.vendor.js>; as=script; rel=preload, </static/js/apollo.6.2.9.vendor.js>; as=script; rel=preload, </static/js/bundle.638cddd6.js>; as=script; rel=preload, </static/js/bundle.db839078.js>; as=script; rel=preload, </static/js/76.d4273231.chunk.js>; as=script; rel=preload, </static/js/536.0bf4fe5d.chunk.js>; as=script; rel=preload, </static/js/8.e12bd67b.chunk.js>; as=script; rel=preload, </static/js/726.542923fa.chunk.js>; as=script; rel=preload, </static/js/StartPage-StartPage.ac26438f.chunk.js>; as=script; rel=preload X-GeoIP-Country: DE X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Referrer-Policy: no-referrer-when-downgrade Feature-Policy: geolocation *;midi *;notifications *;push *;sync-xhr *;microphone *;camera *;magnetometer *;gyroscope *;speaker *;vibrate *;fullscreen *;payment *; X-Frame-Options: SAMEORIGIN Strict-Transport-Security: max-age=31536000; includeSubdomains Content-Security-Policy: default-src 'self'; connect-src *; font-src * data:; frame-src *; img-src * data: blob: https:; media-src *; object-src *; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; Date: Thu, 22 Jan 2026 20:51:35 GMT Transfer-Encoding: chunked Connection: close Connection: Transfer-Encoding Set-Cookie: SalesSource=; Path=/; Expires=Tue, 22 Jan 2036 20:51:34 GMT Set-Cookie: geoipCountry=DE; Path=/; Expires=Tue, 22 Jan 2036 20:51:34 GMT
Open service 95.101.54.216:443 · www.chevalier.fi
2026-01-09 05:10
HTTP/1.1 200 OK Server: nginx/1.25.5 Content-Type: text/html Link: </static/css/style-StartPage-StartPage-272f8fcf.chunk.css>; as=style; rel=preload, </static/css/style-726-eb77abed.chunk.css>; as=style; rel=preload, </static/css/style-cdee2ed2.css>; as=style; rel=preload, </static/js/react.6.2.9.vendor.js>; as=script; rel=preload, </static/js/apollo.6.2.9.vendor.js>; as=script; rel=preload, </static/js/bundle.638cddd6.js>; as=script; rel=preload, </static/js/bundle.db839078.js>; as=script; rel=preload, </static/js/76.d4273231.chunk.js>; as=script; rel=preload, </static/js/536.0bf4fe5d.chunk.js>; as=script; rel=preload, </static/js/8.e12bd67b.chunk.js>; as=script; rel=preload, </static/js/726.542923fa.chunk.js>; as=script; rel=preload, </static/js/StartPage-StartPage.ac26438f.chunk.js>; as=script; rel=preload X-GeoIP-Country: US X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Referrer-Policy: no-referrer-when-downgrade Feature-Policy: geolocation *;midi *;notifications *;push *;sync-xhr *;microphone *;camera *;magnetometer *;gyroscope *;speaker *;vibrate *;fullscreen *;payment *; X-Frame-Options: SAMEORIGIN Strict-Transport-Security: max-age=31536000; includeSubdomains Content-Security-Policy: default-src 'self'; connect-src *; font-src * data:; frame-src *; img-src * data: blob: https:; media-src *; object-src *; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; Date: Fri, 09 Jan 2026 05:10:42 GMT Transfer-Encoding: chunked Connection: close Connection: Transfer-Encoding Set-Cookie: SalesSource=; Path=/; Expires=Wed, 09 Jan 2036 05:10:42 GMT Set-Cookie: geoipCountry=US; Path=/; Expires=Wed, 09 Jan 2036 05:10:42 GMT
Open service 95.101.54.216:443 · app-staging.cgnportal.de
2026-01-09 03:07
HTTP/1.1 200 OK
Content-Type: text/html
Content-Length: 492
Last-Modified: Wed, 17 Dec 2025 09:03:41 GMT
ETag: "694271ed-1ec"
x-frame-options: SAMEORIGIN
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
Content-Security-Policy: default-src 'self'; base-uri 'self'; block-all-mixed-content; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.googleapis.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com https://fonts.googleapis.com data:; img-src * data: blob:; child-src 'self' https://*.cgnportal.de https://*.cgnportal.com; frame-src 'self' https://*.cgnportal.de https://*.cgnportal.com https://*.eu.auth0.com https://app-wallee.com https://login.microsoftonline.com blob:; object-src 'self' blob:; worker-src 'self' https://*.cgnportal.de https://*.cgnportal.com https://*.eu.auth0.com https://app-wallee.com https://login.microsoftonline.com/ blob:; connect-src https://*.cgnportal.de https://*.cgnportal.com https://*.eu.auth0.com https://app-wallee.com https://login.microsoftonline.com/; frame-ancestors 'none';
Accept-Ranges: bytes
x-envoy-upstream-service-time: 14
Expires: Fri, 09 Jan 2026 03:07:31 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Fri, 09 Jan 2026 03:07:31 GMT
Connection: close
Alt-Svc: h3=":443"; ma=93600
Strict-Transport-Security: max-age=600 ; includeSubDomains
Akamai-GRN: 0.d436655f.1767928051.321c8475
Page title: AppPortal | CGN Portal
<!doctype html>
<html lang="en">
<head>
<meta charset="utf-8" />
<title>AppPortal | CGN Portal</title>
<base href="/" />
<meta name="viewport" content="width=device-width, initial-scale=1" />
<link rel="icon" type="image/x-icon" href="/favicon.ico" />
<script type="module" crossorigin src="/assets/index-Bf4s7RWo.js"></script>
<link rel="stylesheet" crossorigin href="/assets/index-CYYZqDsP.css">
</head>
<body>
<div id="root"></div>
</body>
</html>
Open service 95.101.54.216:443 · image.email.littlevillage.johnsonsbaby.com
2026-01-06 18:38
HTTP/1.1 403 Forbidden Server: AkamaiGHost Mime-Version: 1.0 Content-Type: text/html Content-Length: 404 Expires: Tue, 06 Jan 2026 18:38:40 GMT Date: Tue, 06 Jan 2026 18:38:40 GMT Connection: close Page title: Access Denied <HTML><HEAD> <TITLE>Access Denied</TITLE> </HEAD><BODY> <H1>Access Denied</H1> You don't have permission to access "http://image.email.littlevillage.johnsonsbaby.com/" on this server.<P> Reference #18.6d36655f.1767724720.1abfaa4a <P>https://errors.edgesuite.net/18.6d36655f.1767724720.1abfaa4a</P> </BODY> </HTML>
Open service 95.101.54.216:443 · www.chevalier.fi
2026-01-02 19:28
Open service 95.101.54.216:80 · images.supersport.com
2026-01-02 18:57
HTTP/1.1 403 Forbidden
Content-Type: text/html
Access-Control-Allow-Origin: *
Content-Length: 1233
Date: Fri, 02 Jan 2026 18:57:25 GMT
Connection: close
Page title: 403 - Forbidden: Access is denied.
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/>
<title>403 - Forbidden: Access is denied.</title>
<style type="text/css">
<!--
body{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}
fieldset{padding:0 15px 10px 15px;}
h1{font-size:2.4em;margin:0;color:#FFF;}
h2{font-size:1.7em;margin:0;color:#CC0000;}
h3{font-size:1.2em;margin:10px 0 0 0;color:#000000;}
#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;
background-color:#555555;}
#content{margin:0 0 0 2%;position:relative;}
.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}
-->
</style>
</head>
<body>
<div id="header"><h1>Server Error</h1></div>
<div id="content">
<div class="content-container"><fieldset>
<h2>403 - Forbidden: Access is denied.</h2>
<h3>You do not have permission to view this directory or page using the credentials that you supplied.</h3>
</fieldset></div>
</div>
</body>
</html>
Open service 95.101.54.216:443 · images.supersport.com
2026-01-02 18:57
HTTP/1.1 403 Forbidden
Content-Type: text/html
Access-Control-Allow-Origin: *
Content-Length: 1233
Date: Fri, 02 Jan 2026 18:57:22 GMT
Alt-Svc: h3=":443"; ma=93600,h3-29=":443"; ma=93600
Connection: close
Page title: 403 - Forbidden: Access is denied.
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"/>
<title>403 - Forbidden: Access is denied.</title>
<style type="text/css">
<!--
body{margin:0;font-size:.7em;font-family:Verdana, Arial, Helvetica, sans-serif;background:#EEEEEE;}
fieldset{padding:0 15px 10px 15px;}
h1{font-size:2.4em;margin:0;color:#FFF;}
h2{font-size:1.7em;margin:0;color:#CC0000;}
h3{font-size:1.2em;margin:10px 0 0 0;color:#000000;}
#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;
background-color:#555555;}
#content{margin:0 0 0 2%;position:relative;}
.content-container{background:#FFF;width:96%;margin-top:8px;padding:10px;position:relative;}
-->
</style>
</head>
<body>
<div id="header"><h1>Server Error</h1></div>
<div id="content">
<div class="content-container"><fieldset>
<h2>403 - Forbidden: Access is denied.</h2>
<h3>You do not have permission to view this directory or page using the credentials that you supplied.</h3>
</fieldset></div>
</div>
</body>
</html>
Open service 95.101.54.216:443 · app-staging.cgnportal.de
2026-01-02 10:52
HTTP/1.1 200 OK
Content-Type: text/html
Content-Length: 492
Last-Modified: Wed, 17 Dec 2025 09:03:41 GMT
ETag: "694271ed-1ec"
x-frame-options: SAMEORIGIN
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
Content-Security-Policy: default-src 'self'; base-uri 'self'; block-all-mixed-content; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.googleapis.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com https://fonts.googleapis.com data:; img-src * data: blob:; child-src 'self' https://*.cgnportal.de https://*.cgnportal.com; frame-src 'self' https://*.cgnportal.de https://*.cgnportal.com https://*.eu.auth0.com https://app-wallee.com https://login.microsoftonline.com blob:; object-src 'self' blob:; worker-src 'self' https://*.cgnportal.de https://*.cgnportal.com https://*.eu.auth0.com https://app-wallee.com https://login.microsoftonline.com/ blob:; connect-src https://*.cgnportal.de https://*.cgnportal.com https://*.eu.auth0.com https://app-wallee.com https://login.microsoftonline.com/; frame-ancestors 'none';
Accept-Ranges: bytes
x-envoy-upstream-service-time: 2
Expires: Fri, 02 Jan 2026 10:52:43 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Fri, 02 Jan 2026 10:52:43 GMT
Connection: close
Alt-Svc: h3=":443"; ma=93600
Strict-Transport-Security: max-age=600 ; includeSubDomains
Akamai-GRN: 0.6d36655f.1767351163.d05e69e
Page title: AppPortal | CGN Portal
<!doctype html>
<html lang="en">
<head>
<meta charset="utf-8" />
<title>AppPortal | CGN Portal</title>
<base href="/" />
<meta name="viewport" content="width=device-width, initial-scale=1" />
<link rel="icon" type="image/x-icon" href="/favicon.ico" />
<script type="module" crossorigin src="/assets/index-Bf4s7RWo.js"></script>
<link rel="stylesheet" crossorigin href="/assets/index-CYYZqDsP.css">
</head>
<body>
<div id="root"></div>
</body>
</html>
Open service 95.101.54.216:443 · www.chevalier.fi
2025-12-22 21:01
HTTP/1.1 200 OK Server: nginx/1.25.5 Content-Type: text/html Link: </static/css/style-StartPage-StartPage-272f8fcf.chunk.css>; as=style; rel=preload, </static/css/style-726-eb77abed.chunk.css>; as=style; rel=preload, </static/css/style-cdee2ed2.css>; as=style; rel=preload, </static/js/react.6.2.9.vendor.js>; as=script; rel=preload, </static/js/apollo.6.2.9.vendor.js>; as=script; rel=preload, </static/js/bundle.638cddd6.js>; as=script; rel=preload, </static/js/bundle.db839078.js>; as=script; rel=preload, </static/js/76.d4273231.chunk.js>; as=script; rel=preload, </static/js/536.0bf4fe5d.chunk.js>; as=script; rel=preload, </static/js/8.e12bd67b.chunk.js>; as=script; rel=preload, </static/js/726.542923fa.chunk.js>; as=script; rel=preload, </static/js/StartPage-StartPage.ac26438f.chunk.js>; as=script; rel=preload X-GeoIP-Country: US X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Referrer-Policy: no-referrer-when-downgrade Feature-Policy: geolocation *;midi *;notifications *;push *;sync-xhr *;microphone *;camera *;magnetometer *;gyroscope *;speaker *;vibrate *;fullscreen *;payment *; X-Frame-Options: SAMEORIGIN Strict-Transport-Security: max-age=31536000; includeSubdomains Content-Security-Policy: default-src 'self'; connect-src *; font-src * data:; frame-src *; img-src * data: blob: https:; media-src *; object-src *; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; Date: Mon, 22 Dec 2025 21:01:10 GMT Transfer-Encoding: chunked Connection: close Connection: Transfer-Encoding Set-Cookie: SalesSource=; Path=/; Expires=Sat, 22 Dec 2035 21:01:09 GMT Set-Cookie: geoipCountry=US; Path=/; Expires=Sat, 22 Dec 2035 21:01:09 GMT
Open service 95.101.54.216:443 · app-staging.cgnportal.de
2025-12-22 18:53
HTTP/1.1 200 OK
Content-Type: text/html
Content-Length: 492
Last-Modified: Wed, 17 Dec 2025 09:03:41 GMT
ETag: "694271ed-1ec"
x-frame-options: SAMEORIGIN
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
Content-Security-Policy: default-src 'self'; base-uri 'self'; block-all-mixed-content; script-src 'self' 'unsafe-eval' 'unsafe-inline' https://*.googleapis.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com https://fonts.googleapis.com data:; img-src * data: blob:; child-src 'self' https://*.cgnportal.de https://*.cgnportal.com; frame-src 'self' https://*.cgnportal.de https://*.cgnportal.com https://*.eu.auth0.com https://app-wallee.com https://login.microsoftonline.com blob:; object-src 'self' blob:; worker-src 'self' https://*.cgnportal.de https://*.cgnportal.com https://*.eu.auth0.com https://app-wallee.com https://login.microsoftonline.com/ blob:; connect-src https://*.cgnportal.de https://*.cgnportal.com https://*.eu.auth0.com https://app-wallee.com https://login.microsoftonline.com/; frame-ancestors 'none';
Accept-Ranges: bytes
x-envoy-upstream-service-time: 4
Expires: Mon, 22 Dec 2025 18:53:49 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Mon, 22 Dec 2025 18:53:49 GMT
Connection: close
Alt-Svc: h3=":443"; ma=93600
Strict-Transport-Security: max-age=600 ; includeSubDomains
Akamai-GRN: 0.6d36655f.1766429628.1238d9df
Page title: AppPortal | CGN Portal
<!doctype html>
<html lang="en">
<head>
<meta charset="utf-8" />
<title>AppPortal | CGN Portal</title>
<base href="/" />
<meta name="viewport" content="width=device-width, initial-scale=1" />
<link rel="icon" type="image/x-icon" href="/favicon.ico" />
<script type="module" crossorigin src="/assets/index-Bf4s7RWo.js"></script>
<link rel="stylesheet" crossorigin href="/assets/index-CYYZqDsP.css">
</head>
<body>
<div id="root"></div>
</body>
</html>
Open service 95.101.54.216:443 · www.chevalier.fi
2025-12-20 21:54
HTTP/1.1 200 OK Server: nginx/1.25.5 Content-Type: text/html Link: </static/css/style-StartPage-StartPage-272f8fcf.chunk.css>; as=style; rel=preload, </static/css/style-726-eb77abed.chunk.css>; as=style; rel=preload, </static/css/style-cdee2ed2.css>; as=style; rel=preload, </static/js/react.6.2.9.vendor.js>; as=script; rel=preload, </static/js/apollo.6.2.9.vendor.js>; as=script; rel=preload, </static/js/bundle.638cddd6.js>; as=script; rel=preload, </static/js/bundle.db839078.js>; as=script; rel=preload, </static/js/76.d4273231.chunk.js>; as=script; rel=preload, </static/js/536.0bf4fe5d.chunk.js>; as=script; rel=preload, </static/js/8.e12bd67b.chunk.js>; as=script; rel=preload, </static/js/726.542923fa.chunk.js>; as=script; rel=preload, </static/js/StartPage-StartPage.ac26438f.chunk.js>; as=script; rel=preload X-GeoIP-Country: DE X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Referrer-Policy: no-referrer-when-downgrade Feature-Policy: geolocation *;midi *;notifications *;push *;sync-xhr *;microphone *;camera *;magnetometer *;gyroscope *;speaker *;vibrate *;fullscreen *;payment *; X-Frame-Options: SAMEORIGIN Strict-Transport-Security: max-age=31536000; includeSubdomains Content-Security-Policy: default-src 'self'; connect-src *; font-src * data:; frame-src *; img-src * data: blob: https:; media-src *; object-src *; script-src * 'unsafe-inline' 'unsafe-eval'; style-src * 'unsafe-inline'; Date: Sat, 20 Dec 2025 21:54:39 GMT Transfer-Encoding: chunked Connection: close Connection: Transfer-Encoding Set-Cookie: SalesSource=; Path=/; Expires=Thu, 20 Dec 2035 21:54:39 GMT Set-Cookie: geoipCountry=DE; Path=/; Expires=Thu, 20 Dec 2035 21:54:39 GMT